Yandex Protect Anti-phishing warning in Yandex Browser for Desktop from version 16.7.0 to 16.9.0 could be used by a remote attacker for brute-forcing passwords from important web-resource (without opportunity of getting login or important resource's address) with special JavaScript-code.

Yandex Browser for desktop before 17.1.1.227 does not show Protect (similar to Safebrowsing in Chromium) warnigns in web-sites with special content-type, which could be used by remote attacker for prevention Protect warning on own malicious web-site.

Yandex Browser for iOS before 16.10.0.2357 does not properly restrict processing of facetime:// URLs, which allows remote attackers to initiate facetime-call without user's approval and obtain video and audio data from a device via a crafted web site.

Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 15.12.0 to 16.2.0 could be used by a remote attacker for brute forcing passwords from important web-resource (without opportunity of getting login or important resource's address) with special JavaScript-code.

CVE-2016-8506: Thereissuchname

XSS in Yandex Browser's Translator in Yandex Browser for desktop for versions from 15.12.0 to 16.2.0 could be used by a remote attacker for evaluation arbitrary JavaScript-code.

Security WiFi bypass in Yandex Browser for desktop from version 15.10 to 15.12 allows remote attacker to sniff traffic in open or WEP-protected Wi-Fi networks despite of special security mechanism is enabled.